Impact
IBM Business Automation Workflow containers and traditional software are affected by an improper validation of server certificates, where the hostname is not verified against the presented certificate. The flaw corresponds to authentication weakness CWE‑297 and could allow connections to be established with an attacker‑controlled server that advertises a forged certificate, thereby exposing transmitted data to interception or tampering.
Affected Systems
All IBM Business Automation Workflow containers and traditional releases from 24.0.0 through 26.0.0, including interim fixes 005, 007, and 009, are affected. The product is IBM Business Automation Workflow containers and traditional.
Risk and Exploitability
The CVSS score of 3.8 indicates low severity, and the EPSS score is not available. It is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an attacker controlling the endpoint and presenting a fraudulent certificate during a TLS handshake. If successful, the attacker could intercept or alter communications, compromising confidentiality and integrity of the data exchanged with the workflow system.
OpenCVE Enrichment